nix: order each swarm-bao secret reader after the policy unit writing its role

The four readers (matrix-token, queue-agent, grafana-oidc, otel-oidc) log
in against a cert-auth role that their own swarm-bao-*-policy unit writes.
They were ordered after swarm-bao-pki and the store's container but not
after that unit, so on an apply a reader could log in before its role
existed and be refused by `allowed_common_names` until a retry landed
after the role did.

After= plus Wants= on the policy unit, never Requires=: the policy unit
skips by ConditionPathExists once the bootstrap token is gone, and a
skipped unit counts as done for ordering.
This commit is contained in:
atlas 2026-09-24 13:07:18 +02:00 • committed by mara
commit c92bb0dce7
4 changed files with 36 additions and 4 deletions

View file

@ -136,11 +136,19 @@ in
# `Requires=` on an absent unit fails the job outright, so the ordering is # `Requires=` on an absent unit fails the job outright, so the ordering is
# conditional even though the read is not: off-host there is nothing local # conditional even though the read is not: off-host there is nothing local
# to wait for, and the timeout below is what bounds the attempt instead. # to wait for, and the timeout below is what bounds the attempt instead.
#
# The policy unit writes the role this reader logs in with. Ordering
# only: it skips once the bootstrap token is gone, and a skipped unit
# counts as done.
after = lib.optionals baoDeploy.enable [ after = lib.optionals baoDeploy.enable [
"swarm-bao-pki.service" "swarm-bao-pki.service"
"container@${baoCfg.machine}.service" "container@${baoCfg.machine}.service"
"swarm-bao-matrix-token-policy.service"
];
wants = lib.optionals baoDeploy.enable [
"container@${baoCfg.machine}.service"
"swarm-bao-matrix-token-policy.service"
]; ];
wants = lib.optionals baoDeploy.enable [ "container@${baoCfg.machine}.service" ];
requires = lib.optionals baoDeploy.enable [ "swarm-bao-pki.service" ]; requires = lib.optionals baoDeploy.enable [ "swarm-bao-pki.service" ];
before = [ "container@${matrixMachine}.service" ]; before = [ "container@${matrixMachine}.service" ];
wantedBy = [ "container@${matrixMachine}.service" ]; wantedBy = [ "container@${matrixMachine}.service" ];

View file

@ -161,11 +161,19 @@ in
# `Requires=` on an absent unit fails the job outright, so the ordering is # `Requires=` on an absent unit fails the job outright, so the ordering is
# conditional even though the read is not: off-host there is nothing local # conditional even though the read is not: off-host there is nothing local
# to wait for, and the timeout below is what bounds the attempt instead. # to wait for, and the timeout below is what bounds the attempt instead.
#
# The policy unit writes the role this reader logs in with. Ordering
# only: it skips once the bootstrap token is gone, and a skipped unit
# counts as done.
after = lib.optionals baoDeploy.enable [ after = lib.optionals baoDeploy.enable [
"swarm-bao-pki.service" "swarm-bao-pki.service"
"container@${baoCfg.machine}.service" "container@${baoCfg.machine}.service"
"swarm-bao-queue-agent-policy.service"
];
wants = lib.optionals baoDeploy.enable [
"container@${baoCfg.machine}.service"
"swarm-bao-queue-agent-policy.service"
]; ];
wants = lib.optionals baoDeploy.enable [ "container@${baoCfg.machine}.service" ];
requires = lib.optionals baoDeploy.enable [ "swarm-bao-pki.service" ]; requires = lib.optionals baoDeploy.enable [ "swarm-bao-pki.service" ];
# Ordered before hive-c0re, so no agent container renders ahead of an # Ordered before hive-c0re, so no agent container renders ahead of an
# attempt at its credential. `Wants=`, not `Requires=`: a store this # attempt at its credential. `Wants=`, not `Requires=`: a store this

View file

@ -583,11 +583,19 @@ in
# `Requires=` on an absent unit fails the job outright, so the ordering # `Requires=` on an absent unit fails the job outright, so the ordering
# is conditional even though the read is not: off-host there is nothing # is conditional even though the read is not: off-host there is nothing
# local to wait for, and the timeout below bounds the attempt instead. # local to wait for, and the timeout below bounds the attempt instead.
#
# The policy unit writes the role this reader logs in with. Ordering
# only: it skips once the bootstrap token is gone, and a skipped unit
# counts as done.
after = lib.optionals baoDeploy.enable [ after = lib.optionals baoDeploy.enable [
"swarm-bao-pki.service" "swarm-bao-pki.service"
"container@${baoCfg.machine}.service" "container@${baoCfg.machine}.service"
"swarm-bao-grafana-oidc-policy.service"
];
wants = lib.optionals baoDeploy.enable [
"container@${baoCfg.machine}.service"
"swarm-bao-grafana-oidc-policy.service"
]; ];
wants = lib.optionals baoDeploy.enable [ "container@${baoCfg.machine}.service" ];
requires = lib.optionals baoDeploy.enable [ "swarm-bao-pki.service" ]; requires = lib.optionals baoDeploy.enable [ "swarm-bao-pki.service" ];
before = [ "container@${cfg.machine}.service" ]; before = [ "container@${cfg.machine}.service" ];
wantedBy = [ wantedBy = [

View file

@ -766,11 +766,19 @@ in
# `Requires=` on an absent unit fails the job outright, so the ordering # `Requires=` on an absent unit fails the job outright, so the ordering
# is conditional even though the read is not: off-host there is nothing # is conditional even though the read is not: off-host there is nothing
# local to wait for, and the timeout below bounds the attempt instead. # local to wait for, and the timeout below bounds the attempt instead.
#
# The policy unit writes the role this reader logs in with. Ordering
# only: it skips once the bootstrap token is gone, and a skipped unit
# counts as done.
after = lib.optionals baoDeploy.enable [ after = lib.optionals baoDeploy.enable [
"swarm-bao-pki.service" "swarm-bao-pki.service"
"container@${baoCfg.machine}.service" "container@${baoCfg.machine}.service"
"swarm-bao-otel-oidc-policy.service"
];
wants = lib.optionals baoDeploy.enable [
"container@${baoCfg.machine}.service"
"swarm-bao-otel-oidc-policy.service"
]; ];
wants = lib.optionals baoDeploy.enable [ "container@${baoCfg.machine}.service" ];
requires = lib.optionals baoDeploy.enable [ "swarm-bao-pki.service" ]; requires = lib.optionals baoDeploy.enable [ "swarm-bao-pki.service" ];
before = [ "container@${cfg.machine}.service" ]; before = [ "container@${cfg.machine}.service" ];
wantedBy = [ wantedBy = [